← Incident database

2rinkan-api-2026 · Disclosed 2026-04-23

2りんかんイエローハット: unauthorized access and impact

The application API was abused to retrieve membership data; the specific authorization defect or vulnerability is undisclosed. Membership information for 3,179,454 people was leaked, revised from a maximum of 3,455,754. Separately managed payment data was excluded.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    The application API was abused to retrieve membership data; the specific authorization defect or vulnerability is undisclosed.

    [s1]6月19日最終報 §§1-3 / 4月23日第一報
  • Reported fact

    Membership information for 3,179,454 people was leaked, revised from a maximum of 3,455,754. Separately managed payment data was excluded.

    [s1]6月19日最終報 §§1-3 / 4月23日第一報

Timeline

  1. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    Individual notification is complete; the suspended application is being rebuilt. Logout and password reset are planned on reopening.

    [s1]6月19日最終報 §§1-3 / 4月23日第一報

Evidence relevant to prevention

Insufficient evidence

Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The API abuse is established; the notice does not establish a specific IDOR or SQL injection flaw. Revised records replace the original estimate.

Sources

  1. [s1] 2りんかんイエローハット · Primary source

    2りんかんイエローハット:事故に関する公表資料 ↗

    Reviewed 2026-10-09